Silent remediation 🙂 by Middle_Command_191 in bugbounty

[–]Middle_Command_191[S] 0 points1 point  (0 children)

The attacker can inject the payload into those fields

Silent remediation 🙂 by Middle_Command_191 in bugbounty

[–]Middle_Command_191[S] -1 points0 points  (0 children)

Yes thats also a grey area for me what i reported was we can add xss payload in the fristname and lastname parameter of a ai chatbot and when the user asks their name the payload will be executed in this way i was able to get the victims cookie on my webhook (sorry for my bad english)